If a website is pretending to be a legitimate business, asking for money under false pretenses, or trying to collect passwords or identity documents, stop using it. For U.S. consumers, no single agency or form can take down every scam site. Use the channel that matches the harm:
| What happened | Report or contact first | What that route may do |
|---|---|---|
| Money is pending or already gone | Your bank, card issuer, or payment app | Review the transaction, apply its fraud or dispute process, and possibly attempt a reversal |
| Phishing, account theft, crypto fraud, or another online crime | The FBI's Internet Crime Complaint Center | Collect the complaint and share it with FBI offices and law-enforcement partners |
| A fake store or deceptive online business | The FTC's ReportFraud portal | Add the complaint to consumer-fraud information used by law enforcement |
| A phishing or malware warning is needed | Report the exact page to Google Safe Browsing and Bing | Help the services assess browser warnings or search treatment |
| The website should be investigated by its infrastructure provider | The host, registrar, CDN, or security provider | Give the provider a chance to investigate and act under its abuse policy |
You can use several routes. Keep the facts, URLs, dates, and payment details accurate and consistent. None of these reports guarantees a takedown or a refund.
1. Save evidence before the site changes
Scam sites can disappear, change their checkout page, or move to another domain. Capture what you can without signing in again, downloading files, or bypassing a browser warning.
Record:
- The complete web address, including the path after the domain
- The date, time, and time zone when you viewed the page
- Screenshots showing the address bar, offer, checkout page, contact details, and any warning
- The advertisement, social media post, text message, or email that led you there
- Emails with their full headers when possible
- The claimed company name, phone number, email address, payment instructions, and social accounts
- Order numbers, receipts, shipping promises, payment confirmations, and the merchant descriptor on your statement
- For cryptocurrency, the wallet address, network, transaction hash, exchange used, and amount
- For gift cards, the issuer, receipt, code status, and messages from the scammer
Don't send a password, full card number, Social Security number, or identity document just because a page requests it. If an official reporting form requires sensitive information, first check that you're on the correct government or company website. Redact unnecessary details from screenshots and attachments.
If your browser shows a security warning, don't bypass it to gather more evidence. A description of the page and a screenshot may be enough.
2. Protect your money and accounts
A report to the FTC, IC3, a search engine, or a host doesn't stop a payment that is still processing. Contact the bank, card issuer, or payment service through the number on your card, its official app, or a statement - not through contact information supplied by the site.
Explain what happened and ask which process applies:
- Credit or debit card: Ask about the issuer's fraud or billing-dispute process. Be precise about whether you authorized the payment, received anything, or entered into a transaction with a deceptive seller. Don't describe an authorized payment as unauthorized.
- ACH, bank transfer, or peer-to-peer payment: Contact the bank or app immediately and ask whether a stop, recall, reversal, or fraud claim is available. Options can differ when you personally approved the transfer.
- Wire transfer: Ask the sending institution's wire department to attempt a recall as soon as possible. Recovery isn't guaranteed, but delay can reduce the available options.
- PayPal: Follow PayPal's official instructions for reporting suspicious activity or a scam.
- Cryptocurrency: Notify the exchange or service used to send the funds. Provide the wallet address and transaction hash, and include the same information in your IC3 complaint. A completed crypto transfer usually can't be reversed by the sender.
Keep the case number, department name, and date for every call or submission. Don't pay a supposed recovery agent to release a refund. Guaranteed recovery promises are a common follow-up scam.
If you entered a password, change it from a device you trust and change it anywhere else you reused it. Turn on multifactor authentication, starting with your email account. If you downloaded a file or gave someone remote access, stop using that device for banking until it has been checked.
3. Report the site to U.S. agencies
FTC: fake stores and deceptive businesses
Use the FTC's ReportFraud portal for fake online stores, non-delivery, deceptive offers, impersonation, and other consumer scams.
Include:
- The website and any related domains
- What the seller promised and what actually happened
- How you found the site
- The amount and payment method
- Dates, order details, and attempts to contact the seller
- Copies or summaries of supporting evidence
The FTC uses complaints to identify patterns and share information with law enforcement. Treat the submission as a formal record, not as a promise that the FTC will resolve your individual dispute or recover your money.
IC3: online and cyber-enabled crime
File an IC3 complaint when the site is connected to phishing, account compromise, online fraud, cryptocurrency theft, a fraudulent investment, extortion, or another cyber-enabled crime. Technical and financial details are more useful than only saying that the site "looks fake."
Include information such as:
- Suspicious domains, email addresses, IP addresses, or phone numbers
- Cryptocurrency wallet addresses and transaction hashes
- Peer-to-peer payment records
- Messages containing links or requests for credentials
- Evidence that the same group used multiple websites or identities
- Losses involving an online marketplace, investment, or payment account
The FBI's cyber guidance directs people to a local FBI field office or its tips route for an ongoing crime, threat to life, or national-security matter. Don't wait for an IC3 response during an emergency. IC3 also says that its high complaint volume means it can't respond directly to every submission, so not hearing back doesn't show that the report was ignored.
4. Report the exact page to search and security services
Submit the specific suspicious URL, not only the site's domain or business name.
- Google Safe Browsing's reporting form is suited to phishing, malware, or pages designed to steal information.
- Bing's phishing report form lets you submit a suspected phishing page to Microsoft.
These reports may contribute to browser or search warnings. They generally don't remove the site from its host, cancel the domain registration, or refund a purchase. A fake store that doesn't collect passwords or deliver malware may need to be reported primarily to the FTC, payment provider, host, and registrar.
Describe the conduct specifically. For example: "The checkout page collects card details, but the business information appears to be copied from another company." That gives a reviewer more to assess than "this is a scam." Don't report a competitor or business merely because you dislike its prices or policies.
5. Report the host, registrar, or Cloudflare
The domain registrar manages the domain name. The hosting provider stores the website. A content delivery or security service may sit between visitors and the actual host. These can be different companies, so a report to one may not reach the others.
Use public domain-registration or DNS information to identify the registrar and, if possible, the hosting provider. Find an abuse or security contact on each provider's official website.
Include:
- The domain and every relevant page
- The type of abuse, such as phishing, impersonation, or fraudulent non-delivery
- A short, factual explanation of what you observed
- Dates, screenshots, messages, and transaction evidence
- The legitimate business being impersonated, if applicable
- A request to investigate under the provider's abuse policy
A concise report can look like this:
Subject: Suspected phishing or fraudulent website: [domain]
Pages: [exact page addresses]
Observed conduct: [specific facts, dates, and misleading claims]
Evidence: [screenshots, emails, payment records]
Requested action: Please investigate under your abuse policy.
Don't include passwords, executable files, or unnecessary personal data. Avoid threats and repeated duplicate submissions; they can make a legitimate abuse report harder to review.
Cloudflare may not be the origin host
If a domain uses Cloudflare, Cloudflare may provide DNS, caching, proxy, or security services while another company hosts the content. Submit the report through Cloudflare's abuse form and separately report the site to the origin host if you can identify it. A Cloudflare report doesn't guarantee that the site will go offline.
What ICANN can and can't do
ICANN's security-issue guidance points people to its contractual compliance complaint process for problems involving domain registration, phishing, spam, WHOIS accuracy, or a registrar or registry. Use that route when the concern involves the registrar or registry's conduct.
ICANN isn't the website's host and isn't a universal consumer takedown service. Report the site's content, fraud, or payment activity to the relevant host, platform, agency, and financial provider as well.
6. Take extra steps for crypto and investment scams
Preserve the offer, claimed returns, account dashboard, wallet addresses, transaction records, and every message. Don't send more funds to pay a "tax," "verification charge," or "withdrawal fee."
File with the FTC and IC3. If the offer involves securities, commodities, or an investment business, also check the official complaint or tip route for the relevant U.S. regulator. A regulator report doesn't replace notice to the exchange, bank, or payment service that handled your money.
Avoid publishing wallet addresses, phone numbers, or personal information in public posts beyond what is necessary to warn others. Give the complete details to official reporting channels instead.
If you're outside the United States
The steps above use U.S. agencies. If you live elsewhere, use your country's official consumer-protection and cybercrime portals, and contact the payment provider in the country where your account is held.
In the United Kingdom, the National Cyber Security Centre's scam-website reporting page accepts reports of suspected scam websites and says it can investigate and remove some of them. A UK report doesn't replace a bank dispute or a police report when money was lost. Reporting powers and procedures differ in other countries, so a U.S. complaint doesn't automatically create a local case.
What may happen after you report
There is no reliable universal takedown deadline or success rate. The result may be:
- A browser or search warning while the domain remains online
- Suspension by the host, registrar, or service provider
- Removal of a page or payment account
- A referral or intelligence record for a law-enforcement investigation
- No visible change, especially if the site is overseas, uses a disposable domain, or lacks enough evidence for action
Keep confirmation numbers and copies of your submissions. If the site remains active, send a focused follow-up that refers to the original report and adds new evidence. Don't repeatedly visit the page to test it. A domain that returns an error may have moved elsewhere, and a warning doesn't prove that your report caused the change.
Can you report a scam website anonymously?
Some forms may accept limited contact information, while government complaints commonly request identifying and incident details. Don't assume that a VPN or Tor makes an official submission anonymous, and don't use a false identity or invent facts.
A safe contact method can help an investigator ask follow-up questions, but share only what the form needs. If you fear retaliation, ask the relevant agency how it handles confidentiality before submitting. An anonymous report may also make it harder to clarify evidence or recover money.
Immediate checklist
- Stop interacting with the site and save the exact address, screenshots, messages, and payment records.
- Contact your bank, card issuer, or payment service immediately if money is pending or has moved.
- Change exposed passwords and secure affected accounts.
- File with the FTC for consumer fraud and IC3 for cyber-enabled crime.
- Report phishing or malware to Google and Bing, and send a factual abuse report to the host, registrar, or Cloudflare when relevant.
- Save confirmation numbers and watch for recovery scams.
If funds are still moving, call the financial institution first. Save its case number, then use the exact URL and evidence in the other reports.